jason_lunde wrote: » You can indeed do this. Basically in ACS there is a section called "external user databases" (in my version at least). If you go in there you can map you domain to a user group (we do this dynamically for some users). You want to make sure to do your group permissions correct though, so that your AP users dont have permissions on your network devices. There is some planning that needs to go into such a deployment, and make sure to test thoroughly.